CVE-2026-56130: Apache Shiro: Remember-me cookie isn't checked for expiry on the server
"Remember me" cookie age is not verified on the server. This potentially allows an attacker to intercept a valid cookie and reuse it indefinitely, even after the configured expiration time has passed. This issue affects all Apache Shiro versions from 1.2.4 through 2.x, and 3.0.0-alpha-1, only when RememberMe functionality is enabled.
Upgrade to version 3.0.0 or later, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Shiroto a version that resolves this vulnerability.Fixed in 3.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56130?
CVE-2026-56130 has a low severity rating of 2 on a scale of 1 to 5.
What systems are affected by CVE-2026-56130?
CVE-2026-56130 affects all Apache Shiro versions from 1.2.4 through 2.x, and 3.0.0-alpha-1.
How do I fix CVE-2026-56130?
To fix CVE-2026-56130, ensure that the 'remember me' cookie age is verified for expiry on the server.
What is the potential risk of CVE-2026-56130?
The risk of CVE-2026-56130 is that an attacker can intercept a valid 'remember me' cookie and reuse it indefinitely.
When was CVE-2026-56130 published?
CVE-2026-56130 was published on June 24, 2026.